Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a8ca3df4 by Salvatore Bonaccorso at 2026-09-26T22:33:00+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -250,43 +250,43 @@ CVE-2026-100631 (Parse Server is an open source backend
server. In versions prio
CVE-2026-100630 (AVideo contains a stored cross-site scripting vulnerability
in the vid ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-100629 (Capgo (capgo.app backend) before 12.127.5 contains an
authorization fl ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100628 (capgo.app before 12.128.12 fails to enforce an organization's
API key ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100627 (Capgo (Cap-go/capgo.app) server backend Supabase functions
contain an ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100626 (capgo through 12.128.2 contains an insecure direct object
reference vu ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100625 (Capgo (capgo.app) exposes a native build TUS upload proxy
(supabase/fu ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100624 (Capgo.app before 12.264.5 does not enforce upload expiry or
build life ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100623 (Capgo (capgo.app) exposes the legacy membership table
public.org_users ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100622 (capgo.app through 12.129.0 fails to verify deletion status
when servin ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100621 (Capgo (capgo.app) contains an incomplete
access-control/content-lock e ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100620 (Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected
by an ov ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100619 (Capgo (capgo.app) blocks direct user inserts into the
public.manifest ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100618 (Capgo (capgo.app) is affected by an authorization flaw in the
app icon ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100617 (Cap-go capgo.app fails to validate that principals in
channel_permissi ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100616 (capgo.app is an over-the-air update platform for Capacitor
apps. In al ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100615 (Cap-go capgo.app before 12.267.1 fails to validate target API
key priv ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100614 (Capgo before 12.244.1 contains a cross-tenant integrity
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100613 (capgo.app is an over-the-air (OTA) update platform for
Capacitor apps. ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100612 (Capgo (capgo.app) through version 12.261.0 contains an
incomplete acce ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100611 (Capgo (capgo.app backend, versions \u2264 12.261.0)
improperly restric ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-100610 (Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id
and PATCH ...)
NOT-FOR-US: Flowise
CVE-2026-100609 (Flowise (npm packages `flowise` and `flowise-components`)
through 3.1. ...)
@@ -310,15 +310,15 @@ CVE-2026-100601 (ClawHub (openclaw/clawhub)
application/backend contains a serve
CVE-2026-100600 (ClawHub (the openclaw/clawhub application/backend) does not
bind anony ...)
NOT-FOR-US: OpenClaw
CVE-2026-100315 (A vulnerability was detected in mathurvishal
CloudClassroom-PHP-Projec ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-100314 (A security vulnerability has been detected in mathurvishal
CloudClassr ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-100313 (A weakness has been identified in mathurvishal
CloudClassroom-PHP-Proj ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-100312 (A security flaw has been discovered in mathurvishal
CloudClassroom-PHP ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-100311 (A vulnerability was identified in mathurvishal
CloudClassroom-PHP-Proj ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-XXXX [GHSA-3q6v-r5mr-hxv8: Fix quadratic-time table start detection
on long paragraphs]
- php-league-commonmark 2.10.3-1
NOTE:
https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8
@@ -545,7 +545,7 @@ CVE-2026-100546 (OpenClaw (npm package `openclaw`) versions
>= 2026.7.2 and < 20
CVE-2026-100545 (OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly
enforces ...)
NOT-FOR-US: OpenClaw
CVE-2026-100544 (openclaw's @openclaw/voice-call package before 2026.8.1
launches the c ...)
- TODO: check
+ NOT-FOR-US: openclaw/voice-call
CVE-2026-100543 (OpenClaw (npm package openclaw) before 2026.8.1 could include
determin ...)
NOT-FOR-US: OpenClaw
CVE-2026-100542 (OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and <
2026.8.1 ...)
@@ -569,9 +569,9 @@ CVE-2026-100534 (OpenClaw versions before 2026.8.1 contain
an authorization bypa
CVE-2026-100533 (OpenClaw versions before 2026.8.1 contain a path traversal
vulnerabili ...)
NOT-FOR-US: OpenClaw
CVE-2026-100532 (@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp
login to ...)
- TODO: check
+ NOT-FOR-US: penclaw/whatsapp Node.js module
CVE-2026-100531 (The @openclaw/slack npm package before 2026.8.1 contains an
authorizat ...)
- TODO: check
+ NOT-FOR-US: openclaw/slack npm package
CVE-2026-100530 (OpenClaw versions before 2026.8.1 fail to bind working
directory conte ...)
NOT-FOR-US: OpenClaw
CVE-2026-100529 (OpenClaw versions before 2026.8.1 contain an authorization
scope widen ...)
@@ -585,15 +585,15 @@ CVE-2026-100526 (OpenClaw's Discord integration (npm
package @openclaw/discord)
CVE-2026-100525 (The OpenClaw Prometheus diagnostics plugin
(@openclaw/diagnostics-prom ...)
NOT-FOR-US: OpenClaw
CVE-2026-100524 (Cotonti through 1.0.0 contains a cross-site request forgery
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-100523 (Cotonti through 1.0.0 contains an open redirect vulnerability
in messa ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-100522 (Cotonti through 1.0.0 contains a reflected cross-site
scripting vulner ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-100521 (Cotonti through 1.0.0 contains a reflected cross-site
scripting vulner ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-100520 (Laranode versions before 1.2.1 contain a path traversal
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Laranode
CVE-2026-100505 (Ghidra versions 11.2 through 12.1.4 contain a heap
out-of-bounds read ...)
TODO: check
CVE-2026-100504 (Ghidra versions through 12.1.4 contain a stack-based
out-of-bounds wri ...)
@@ -601,25 +601,25 @@ CVE-2026-100504 (Ghidra versions through 12.1.4 contain a
stack-based out-of-bou
CVE-2026-100503 (Ghidra versions through 12.1.4 contain a heap use-after-free
vulnerabi ...)
TODO: check
CVE-2026-100502 (Flame through 2.4.0 contains an insufficient session
expiration vulner ...)
- TODO: check
+ NOT-FOR-US: Flame
CVE-2026-100501 (Flame through 2.4.0 contains an improper restriction of
excessive auth ...)
- TODO: check
+ NOT-FOR-US: Flame
CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation
bypass vulner ...)
TODO: check
CVE-2026-100418 (Flame through 2.4.0 contains an information exposure
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Flame
CVE-2026-100417 (RustDesk before 1.5.0 on Windows fails to enforce the one-way
file tra ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-100391 (MediaFlow Proxy through 2.4.9 contains a server-side request
forgery v ...)
- TODO: check
+ NOT-FOR-US: MediaFlow Proxy
CVE-2026-100390 (Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse
IPv6 addres ...)
- TODO: check
+ NOT-FOR-US: Zoraxy
CVE-2026-100389 (GestSup versions before 3.2.61 contain a remote code
execution vulnera ...)
- TODO: check
+ NOT-FOR-US: GestSup
CVE-2026-100388 (RustDesk versions before 1.5.0 fail to properly validate file
transfer ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-100387 (pgPointcloud through 1.2.5 contains a heap out-of-bounds read
vulnerab ...)
- TODO: check
+ NOT-FOR-US: pgPointcloud
CVE-2026-100383 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-100382 (Improper Neutralization of Special Elements used in an OS
Command ('OS ...)
@@ -637,13 +637,13 @@ CVE-2026-100377 (Exposure of Sensitive Information to an
Unauthorized Actor vuln
CVE-2026-100376 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
TODO: check
CVE-2026-100373 (OpenMetadata through 2.0.2 contains a server-side request
forgery vuln ...)
- TODO: check
+ NOT-FOR-US: OpenMetadata
CVE-2026-100372 (ClipBucket v5 before 5.5.3-#197 contains a path traversal
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2026-100369 (CliInvoke and its formerly named `AlastairLundy.CliInvoke`
package are ...)
- TODO: check
+ NOT-FOR-US: CliInvoke
CVE-2026-100368 (CliInvoke is a .NET library for invoking command-line
programs, and it ...)
- TODO: check
+ NOT-FOR-US: CliInvoke
CVE-2026-100310 (GNU libextractor before 1.16 loads plugins from an untrusted
search pa ...)
- libextractor 1:1.17-1
NOTE: https://www.openwall.com/lists/oss-security/2026/09/25/25
@@ -1290,33 +1290,33 @@ CVE-2026-13179 (The WP Maps \u2013 Google
Maps,OpenStreetMap,Mapbox,Store Locato
CVE-2026-12037 (The Asset CleanUp: Page Speed Booster plugin for WordPress is
vulnerab ...)
NOT-FOR-US: WordPress plugin
CVE-2026-100306 (TDuck survey form through 6.0 fails to validate write
passwords on sub ...)
- TODO: check
+ NOT-FOR-US: TDuck survey
CVE-2026-100305 (TDuck survey form through 6.0 fails to enforce form fill-in
restrictio ...)
- TODO: check
+ NOT-FOR-US: TDuck survey
CVE-2026-100304 (TDuck survey form 6.0 contains an information disclosure
vulnerability ...)
- TODO: check
+ NOT-FOR-US: TDuck survey
CVE-2026-100303 (TDuck survey form through 6.0 lacks authorization checks on
FormThemeC ...)
- TODO: check
+ NOT-FOR-US: TDuck survey
CVE-2026-100248 (The Rattadan Cosmowarp smart contract before 56c6147 can have
a compar ...)
- TODO: check
+ NOT-FOR-US: Rattadan Cosmowarp smart contract
CVE-2026-100237 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-100230 (Input Leap (aka input-leap) through 3.0.3, when the
non-default --enab ...)
TODO: check
CVE-2026-100192 (X-SpringBoot through 6.0 exposes appKey and appSecret
credentials in t ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-100190 (The AIL Framework crawler splash domain page
(showDomain.html) is vuln ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2026-100187 (The Onion module in AIL Framework contained a performance
shortcut in ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2026-100177 (The AIL Framework crawler task creation API
(api_add_crawler_task) con ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2026-100176 (The AIL Framework's username timeline feature is vulnerable
to stored ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2026-100174 (The AIL Framework tag selector component
(var/www/static/js/tags.js) i ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2026-100172 (The AIL Framework (ail-project/ail-framework) contains a
stored cross- ...)
- TODO: check
+ NOT-FOR-US: AIL Framework
CVE-2025-51457 (D-Link DAP-2610 up to 2.06B08r099 contains an authenticated
command in ...)
NOT-FOR-US: D-Link
CVE-2025-14814 (The CSS & JavaScript Toolbox plugin for WordPress is
vulnerable to Sto ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits